Bedford Group of Drainage Boards



Similar documents
River Stour (Kent) Internal Drainage Board Risk Management Strategy and Policy

Waveney Lower Yare & Lothingland Internal Drainage Board Risk Management Strategy and Policy

RISK MANAGEMENT STRATEGY

The Risk Management strategy sets out the framework that the Council has established.

Shepway District Council Risk Management Policy

Bridgend County Borough Council. Corporate Risk Management Policy

Risk Management Policy and Framework

Version: 3.0. Effective From: 19/06/2014

RISK MANAGEMENT POLICY AND STRATEGY. Document Status: Draft. Approved by. Appendix 1. Originator: A Struthers. Updated: A Struthers

Confident in our Future, Risk Management Policy Statement and Strategy

Risk Management Policy

RISK MANAGEMENT POLICY. Version 3

A Risk Management Standard

AFTRS Health and Safety Risk Management Policy

Risk Management Policy. Corporate Governance Risk Management Policy

Risk Management: Coordinated activities to direct and control an organisation with regard to risk.

RISK MANAGEMENT GUIDANCE FOR GOVERNMENT DEPARTMENTS AND OFFICES

RISK AND OPPORTUNITY MANAGEMENT STRATEGY

MARCH Strategic Risk Policy Update March 2012 v1.10.doc

Risk Management. Policy

RISK MANAGEMENT POLICY

ENTERPRISE RISK MANAGEMENT FRAMEWORK

How To Manage Risk In Ancient Health Trust

HEALTH, SAFETY, ENVIRONMENT AND COMMUNITY MANAGEMENT STANDARDS. OCTOBER ISSUE No 01. Doc No: HSEC MS 001

TRANSPORT FOR LONDON SAFETY, HEALTH AND ENVIRONMENT ASSURANCE COMMITTEE

The Lowitja Institute Risk Management Plan

Measuring your capabilities in Fleet Safety Management ACC Fleet Saver

Compliance Management Framework. Managing Compliance at the University

CONTROLLED DOCUMENT. Number: Version Number: 4. On: 25 July 2013 Review Date: June 2016 Distribution: Essential Reading for: Information for:

Risk Management Policy

Discipline: Technical Services Category: Procedure. Risk Management RM Applicability. ARTC Network Wide. Interstate Network.

Risk Management Framework

Risk Management Strategy

Title: Rio Tinto management system

Incident reporting procedure

Corporate Risk Management Policy

Insurance management policy and guidelines. for general government sector, September 2007

Business Continuity Management Policy

V1.0 - Eurojuris ISO 9001:2008 Certified

RISK ASSESSMENT POLICY

Hazard Identification, Risk Assessment and Management Procedure. Documentation Control

Safety Management System (SMS) Guidelines

Revised Risk Management Policy and Framework. Report by Head of Finance

ENTERPRISE RISK M A NAGEMENT POLICY

HEALTH SAFETY & ENVIRONMENT MANAGEMENT SYSTEM

University of New England Compliance Management Framework and Procedures

Business Continuity Management Policy

Six steps to Occupational Health and Safety

TRUST SECURITY MANAGEMENT POLICY

DIT HEALTH AND SAFETY OFFICE

Managing Risk in Procurement Guideline

SOUTHERN RURAL WATER POLICY RISK MANAGEMENT POLICY

RISK MANAGEMENT STRATEGY

GUIDANCE MATERIAL GUIDANCE ON THE USE OF POSITIVE PERFORMANCE INDICATORS TO IMPROVE WORKPLACE HEALTH AND SAFETY

Northern Ireland Blood Transfusion Service

Clinical Incident Management Policy

Compensation Claims. Ministry of Defence. LONDON: The Stationery Office 9.25

Safety Management Systems (SMS) guidance for organisations

Integrated Risk Management:

How To Ensure That Sovini Is A Successful Business

INCIDENT POLICY Page 1 of 13 November 2015

Business Continuity Policy and Business Continuity Management System

NORTH HAMPSHIRE CLINICAL COMMISSIONING GROUP BUSINESS CONTINUITY MANAGEMENT POLICY AND PLAN (COR/017/V1.00)

ERM Program. Enterprise Risk Management Guideline

1.0 Policy Statement / Intentions (FOIA - Open)

Audit Committee, 28 November. HCPC Project Risk Management. Executive summary and recommendations. Introduction

RISK MANAGEMENT POLICY

POLICY : CORPORATE RISK MANAGEMENT

Risk Management Strategy

Risk Management Guide

Safety Excellence Matrix

South West Lincolnshire NHS Clinical Commissioning Group Business Continuity Policy

VICTORIAN GOVERNMENT DEPARTMENT ENVIRONMENTAL MANAGEMENT SYSTEM MODEL MANUAL

RISK MANAGEMENT FOR INFRASTRUCTURE

GLASGOW SCHOOL OF ART OCCUPATIONAL HEALTH AND SAFETY POLICY. 1. Occupational Health and Safety Policy Statement 1

Information Governance Strategy

Service and Improvement Plan

RISK ASSESSMENT MATRIX GUIDANCE NOTES

RISK MANAGEMENT TOOLKIT

Business Continuity (Policy & Procedure)

Council Meeting Agenda 27/07/15

Risk Management Strategy and Policy. The policy provides the framework for the management and control of risk within the GOC

BUSINESS CONTINUITY STRATEGY

Hazard Identification, Risk Assessment and Control Management

13 ENVIRONMENTAL AND SOCIAL MANAGEMENT SYSTEM

CODE OF PRACTICE. Safety Management. Occupational Safety and Health Branch Labour Department CODE OF PRACTICE ON SAFETY MANAGEMENT 1

Risk Management Policy Adopted by:

A Review of the NHSLA Incident Reporting and Management and Learning from Experience Standards. Assessment Outcomes. April March 2004

Risk Management Framework

NORTH AYRSHIRE COUNCIL CORPORATE ASSET MANAGEMENT STRATEGY JANUARY 2013

AS/NZS 4801:2001. Safety Management Systems (SMS) Self-Assessment Checklist. Revision 1 (January 2014)

Standard 1. Governance for Safety and Quality in Health Service Organisations. Safety and Quality Improvement Guide

Transcription:

Bedford Group of Drainage Boards Risk Management Strategy Risk Management Policy January 2010 1

Contents 1. Purpose, Aims & Objectives 2. Accountabilities, Roles & Reporting Lines 3. Skills & Expertise 4. Embedding Risk Management 5. Risk and the Decision Making Processes 6. Risk Evaluation 7. Risk Control 8. Supporting Innovation & Improvement Appendices A Risk Management Strategy Statement B Risk Management Policy Document 2

Risk Management Strategy 1. Purpose, Aims and Objectives 1.1 The purpose of the Groups Corporate Risk Management Strategy is to effectively manage potential opportunities and threats to the individual Boards achieving their objectives. See attached Corporate Risk Management Policy Statement, Appendix A. 1.2 The Groups Corporate Risk Management Strategy has the following aims and objectives; Integration of Risk Management into the culture of the Boards Raising awareness of the need for Risk Management by all those connected with the delivery of services (including partners) Enabling the Boards to anticipate and respond to changing social, environmental and legislative conditions Minimisation of injury, damage, loss and inconvenience to staff, members of the public, service users, assets etc. arising from or connected with the delivery of the Boards services Introduction of a robust framework and procedures for identification, analysis, assessment and management of risk, and the reporting and recording of events, based on best practice Minimisation of the cost of risk 1.3 To achieve these aims and objectives, the following strategy is proposed; Establish clear accountabilities, roles and reporting lines for all employees Acquire and develop the necessary skills and expertise Provide for risk assessment in all decision making processes of the Boards Develop a resource allocation framework to allocate (target) resources for risk management Develop toolkits, procedures and guidelines for use across the Boards Develop arrangements to measure performance of Risk Management activities against the aims and objectives To make all partners and service providers aware of the Boards expectations on risk, both generally as set out in its Risk Management Policy and where necessary in particular areas of the Boards operations.. 1.4 The Bedford Group has adopted the Audit Commission definition of Risk: 3

Risk is the threat that an event or action will adversely affect the organisation s ability to achieve its objectives and to successfully execute its strategies. 2. Accountabilities, Roles and Reporting Lines 2.1 A framework has been implemented that has addressed the following issues: The different types of risk Strategic and Operational Where it should be managed Corporate, Departmental and Risk Management Unit roles and accountabilities The need to drive the policy throughout the Group Prompt reporting of accidents, losses, changes etc. 2.2 In many cases, risk management follows existing service management arrangements. 2.3 Strategic risk is best managed by the Executive Working Group (EWG) who will report to the Joint Management Committee (JMC) and then to the individual Boards. 2.4 The Groups Clerk and Chief Executive will be responsible for the Boards overall risk management strategy, and will report directly to the EWG. 2.5 The Groups Director of Operations will be responsible for the Groups overall Health and Safety policy and will report to the Clerk. 2.6 It is envisaged that the development of a risk management strategy will encourage ownership of risk and will allow for easier monitoring and reporting on remedial actions / controls. 3. Skills and Expertise 3.1 Having established roles and responsibilities for risk management, the Group must ensure that it has the skills and expertise necessary. It will achieve this by providing Risk Management Training for Executive Officers and where appropriate providing awareness courses that address the individual needs of both the manual workforce and office staff. 3.2 Training will include seminars focusing on best practice in risk management and awareness courses will also focus on specific risks in areas such as the following: Partnership working Project management Employment Law 4

Operation of Board vehicles and equipment Manual labour tasks e.g. Health and Safety issues 4.Embedding Risk Management Risk management is an important part of the service planning process. This will enable both strategic and operational risk, as well as the accumulation of risks from a number of areas to be properly considered. Over time the Group aims to be able to demonstrate that there is a fully embedded process. This strategy and the information contained within the appendices provides a framework to be used by all levels of staff and Members in the implementation of risk management as an integral part of good management. 5.Risks and the Decision Making Process 5.1 Risk needs to be addressed at the point at which decisions are being taken.. Where Members and Officers are asked to make decisions they should be advised of the risks associated with recommendations being made. The training described in the preceding section will enable this to happen. 5.2 The Board will need to demonstrate that it took reasonable steps to consider the risks involved in a decision. 5.3 A template has been developed for use with all significant decision reports. 5.4 There needs to be a balance struck between efficiency of the decision making process and the need to address risk. Risk assessment is seen to be particularly valuable in options appraisal. All significant decision reports to the EWG, JMC or individual Boards. (including new and amended policies and strategies) should include an assessment of risk to demonstrate that risks (both threats and opportunities) have been addressed. 5.5 This process does not guarantee that decisions will always be right but it will demonstrate that the risks have been considered and the evidence will support this. 6. Risk Evaluation 6.1 Managers have been made aware that there are a number of tools that can be used to help identify potential risks: Workshops. Scenario planning. 5

Analysing past claims and other losses. Analysing past corporate incidents/failures. Health & safety inspections. Induction training. Performance Review & Development interviews. Staff and customer feedback. 6.2 Having identified areas of potential risk, they must be analysed by: An assessment of impact. An assessment of likelihood. This is to be done by recording the results using the risk matrix below: RISK ASSESSMENT MATRIX Likelihood of occurrence HIGH MEDIUM LOW Low Impact High Likelihood 3 Low Impact Medium Likelihood 2 Low Impact Low Likelihood 1 Medium Impact High Likelihood 6 Medium Impact Medium Likelihood 4 Medium Impact Low Likelihood 2 High Impact High Likelihood 9 High Impact Medium Likelihood 6 High Impact Low Likelihood 3 LOW MEDIUM HIGH Impact on the Business The high, medium and low categories for impact and likelihood are defined as follows: IMPACT High will have a catastrophic effect on the operation/service delivery. May result in major financial loss (over 100,000). Major service disruption (+ 5 days) or impact on the public. Death of an individual or several people. Complete failure of project or extreme delay (over 2 months). Many individual personal details compromised/revealed. Adverse publicity in national press. Medium will have a noticeable effect on the operation/service delivery. May result in significant financial loss (over 25,000). Will cause a degree 6

of disruption (2 5 days) or impact on the public. Severe injury to an individual or several people. Adverse effect on project/significant slippage. Some individual personal details compromised/revealed. Adverse publicity in local press. Low where the consequences will not be severe and any associated losses and or financial implications will be low (up to 10,000). Negligible effect on service delivery (1 day). Minor injury or discomfort to an individual or several people. Isolated individual personal detail compromised/revealed. NB A number of low incidents may have a significant cumulative effect and require attention. LIKELIHOOD High very likely to happen. (matrix score 3) Medium likely to happen infrequently and difficult to predict. (matrix score 2) Low most unlikely to happen. (matrix score1 ) 7.0 Risk Control 7.1 Using the risk matrix produces a risk rating score that will enable risks to be prioritised using one or more of the four T s Tolerate - score >2 - accept the risk Treat - score 3 4 - take cost effective in-house actions to reduce the risk Transfer score 6 - let someone else take the risk (e.g. by insurance or passing responsibility for the risk to a contractor) Terminate score 9 - agree that the risk is too high and do not proceed with the project or activity 7.2 Risk assessment and risk matrices provide a powerful and easy to use tool for the identification, assessment and control of business risk. It enables managers to consider the whole range of categories of risk affecting a business activity. The technique can assist in the prioritisation of risks and decisions on allocation of resources. Decisions can then be made concerning the adequacy of existing control measures and the need for further action. It can be directed at the business activity as a whole or on individual departments/sections/functions or indeed projects. 8.Supporting Innovation and Improvement 8.1 Risk Management will be incorporated into the business planning process for the Group with a risk assessment of all business aims being undertaken as part of the annual Estimates process. 7

8.2 The Groups internal auditor will have a role in reviewing the effectiveness of control measures that have been put in place to ensure that risk management measures are working. Appendix A RISK MANAGEMENT STRATEGY STATEMENT The Group believes that risk is a feature of all businesses. Some risks will always exist and can never be eliminated: they therefore need to be appropriately managed. The Group recognises that it has a responsibility to manage hazards and risks and supports a structured and focused approach to managing them by approval each year of a Risk Management Strategy. In this way the Group will improve its ability to achieve its strategic objectives and enhance the value of services it provides to the community. The Groups Risk Management objectives are to: Embed risk management into the culture and operations of the Group Adopt a systematic approach to risk management as an integral part of service planning and performance management Manage risk in accordance with best practice Anticipate and respond to changing social, environmental and legislative requirements Ensure all employees have clear responsibility for both the ownership and cost of risk and the tools to effectively reduce / control it These objectives will be achieved by: Establishing clear roles, responsibilities and reporting lines within the organisation for risk management Incorporating risk management in the Groups decision making and operational management processes Reinforcing the importance of effective risk management through training Incorporating risk management considerations into Service / Business Planning, Project Management, Partnerships & Procurement Processes Monitoring risk management arrangements on a regular basis The benefits of Risk Management include: 8 Safer environment for all Improved public relations and reputation for the organisation Improved efficiency within the organisation Protect employees and others from harm

Reduction in probability / size of uninsured or uninsurable losses Competitive Insurance Premiums (as insurers recognise the Board as being a low risk ) Maximise efficient use of available resources. Appendix B RISK MANAGEMENT POLICY DOCUMENT In all types of undertaking, there is the potential for events and consequences that may either be opportunities for benefit or threats to success. Internal Drainage Boards are no different and risk management is increasingly recognised as being central to their strategic management. It is a process whereby Internal Drainage Boards methodically address the risks associated with what they do and the services which they provide. The focus of good risk management is to identify what can go wrong and take steps to avoid this or successfully manage the consequences. Risk management is not just about financial management; it is about achieving the objectives of the organisation to deliver high quality public services. The failure to manage risks effectively can be expensive in terms of litigation and reputation, the ability to achieve desired targets, and, eventually, the local community s rate and council tax bills. Internal Drainage Boards need to keep under review and, if need be, strengthen their own corporate governance arrangements, thereby improving their stewardship of public funds and providing positive and continuing assurance to taxpayers. The Boards in the Bedford Group already look at risk as part of their day to day activities but there is now a need to look at, adapt, improve where necessary and document existing processes. The importance of looking afresh at risk comes in the wake of a more demanding society, bold initiatives and more challenge when things go wrong. It also arises because of the significant changes taking place as a result of the Defra IDB Review, the Pitt Review and the Flood and Water Management Bill. Internal Drainage Boards currently face pressures that potentially give rise to a range of new and complex risks and which suggest that risk management is more important now than at any other time.. Members are ultimately responsible for risk management because risks threaten the achievement of policy objectives. As a minimum, the members should, at least once each year,: take steps to identify and update key risks facing the Board; evaluate the potential consequences to the Group and the individual Boards if an event identified as a risk takes place; and 9

decide upon appropriate measures to avoid, reduce or control the risk or its consequences. This Risk Management Policy document is designed to be a living document which will be continually updated when new risks are identified or when existing risks change. The assessment of potential impact will be classified as high, medium or low. At the same time it will assess how likely a risk is to occur and this will enable the Board to decide which risks it should pay most attention to when considering what measures to take to manage the risks. After identifying and evaluating risks the responsible officer will need to decide upon appropriate measures to take in order to avoid, reduce or control the risks or their consequences. 10

11